File name:

7e1f1503df765cca5e099891b94e318a2ef95081ba2af1eb6d417cc884bfdbfe

Full analysis: https://app.any.run/tasks/16548114-eb92-4830-b637-2626e97ec608
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: March 24, 2026, 22:48:00
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
loader
susp-powershell
stealer
stealc
vidar
xor-url
generic
Indicators:
MIME: application/javascript
File info: JavaScript source, ASCII text, with very long lines (65299)
MD5:

0AA8D64E726C4A57ADB5C88F9115996B

SHA1:

901169527507FF9E662CF64D8E361F359308970D

SHA256:

7E1F1503DF765CCA5E099891B94E318A2EF95081BA2AF1EB6D417CC884BFDBFE

SSDEEP:

1536:tp+1ZTPR2t4tXbih05ve8/pwgrEpc9t0vSAIAxCs:MFRIpk0vSAV

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loader pattern has been found

      • powershell.exe (PID: 4692)
    • Dynamically loads an assembly (POWERSHELL)

      • powershell.exe (PID: 4692)
    • XORed URL has been found (YARA)

      • notepad.exe (PID: 6988)
    • STEALC has been detected (SURICATA)

      • notepad.exe (PID: 6988)
    • VIDAR has been detected (YARA)

      • notepad.exe (PID: 6988)
    • Actions looks like stealing of personal data

      • notepad.exe (PID: 6988)
    • Steals credentials from Web Browsers

      • notepad.exe (PID: 6988)
  • SUSPICIOUS

    • Possibly malicious use of IEX has been detected

      • powershell.exe (PID: 4692)
    • Uses base64 encoding (POWERSHELL)

      • powershell.exe (PID: 4692)
    • Searches for installed software

      • notepad.exe (PID: 6988)
    • Possible stealing from crypto wallets

      • notepad.exe (PID: 6988)
    • Possible stealing from password managers

      • notepad.exe (PID: 6988)
    • Contacting a server suspected of hosting an CnC

      • notepad.exe (PID: 6988)
    • Possible stealing from browsers

      • notepad.exe (PID: 6988)
    • Multiple wallet extension IDs have been found

      • notepad.exe (PID: 6988)
  • INFO

    • Disables trace logs

      • powershell.exe (PID: 4692)
    • Gets data length (POWERSHELL)

      • powershell.exe (PID: 4692)
    • Reads security settings of Internet Explorer

      • notepad.exe (PID: 6988)
    • Creates files in the program directory

      • notepad.exe (PID: 6988)
    • There is functionality for taking screenshot (YARA)

      • notepad.exe (PID: 6988)
    • Application launched itself

      • chrome.exe (PID: 7460)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Vidar

(PID) Process(6988) notepad.exe
BrowserExtensionsID (238)nkbihfbeogaeaoehlefnkodbefgpgknn
djclckkglechooblngghdinmeemkbgci
ejbalbakoplchlghecdalmeeeajnimhm
ibnejdfjmmkpcnlpebklmnkoeoihofec
ffnbelfdoeiohenkjibnmadjiehjhajb
kncchdigobghenbbaddojjnnaogfppfj
fnjhmkhhmkbjkkabndcnnogagogbneec
cphhlgmgameodnhkjdmkpanlelnlohao
nhnkbkgjikgcigadomkphalanndcapjk
kpfopkelmapcoipemfendmdcghnegimn
aiifbnbfobpmeekipheeijimdpnlpgpp
dmkamcknogkgcdfhhbddcghachkejeap
cnmamaachppnkjgnildpdmkaakejnhae
jojhfeoedkpkglbfimdfabpdfjaoolaf
flpiciilemghbmfalicajoolhkkenfel
aeachknmefphepccionboohckonoeemg
cgeeodpfagjceefieflmdfphplkenlfk
pdadjkfkgcafgbceimcpbkalnfnepbnk
acmacodkjbdgmoleebolmdjonilkdbch
bfnaelmomeimhlpmgjnjophhpkkoljpa
fhilaheimglignddkjgofkcbgekhenbh
mgffkfbidihjpoaomajlbgchddlicgpn
lpfcbjknijpeeillifnkikgncikgfhdo
bhhhlbepdkbapadjdnnojkbgioiodbic
dkdedlpgdmmkkfjabffeganieamfklkm
hcflpincpppdclinealmandijcmnkbgn
mnfifefkajgofkcjkemidiaecocnkjeh
jnkelfanjkeadonecabehalmbgpfodjm
kjmoohlgokccodicjjfebfomlbljgfhk
ppbibelpcjmhbdihakflkdcoccbgbkpo
pnndplcbkakcplkjnolgbkdgjikjednm
egjidjbpglichdcondbcbdnbeeppgdph
aholpfdialjgjfhomihkjbmgjidlcdno
jnlgamecbpmbajjfhmmmlhejkemejdma
kkpllkodjeloidieedojogacfhpaihoh
mcohilncbfahbmgdjkbpemcciiolgcge
epapihdplajcdnnkdeiahlgigofloibg
gjagmgiddbbciopjhllkdnddhcglnemk
bgpipimickeadkjlklgciifhnalhdjhe
phkbamefinggmakgklpkljjmgibohnba
cjmkndjhnagcfbpiemnkdpomccnjblmj
aijcbedoijmgnlmjeegjaglmepbmpkpi
fiedbfgcleddlbcmgdigjgdfcggjcion
nngceckbapebfimnlniiiahkandclblb
fmhmiaejopepamlcjkncpgpdjichnecm
oboonakemofpalcgghocfoadofidjkkk
hbbgbephgojikajhfbomhlmmollphcad
opfgelmcmbiajamepnmloijbpoleiama
fiikommddbeccaoicoejoniammnalkfa
bgjogpoidejdemgoochpnkmdjpocgkha
jgaaimajipbpdogpdglhaphldakikgef
fcfcfllfndlomdhbehjjcoimbgofdncg
dngmlblcodfobpdpecaadgfbcggfjfnm
kppfdiipphfccemcignhifpjkapfbihd
lgmpcpglpngdoalbgeoldeajfclnhafa
onhogfjeacnfoofkfgppdlbmlmnplgbn
mmmjbcfofconkannjonfmjjajpllddbg
loinekcabhlmhjjbocijdoimmejangoa
heefohaffomkkkphnlpohglngmbcclhi
idnnbdplmphpflfnlkomgpfbpcgelopg
anokgmphncpekkhclmingpimjmcooifb
cnncmdhjacpkmjmkcafchppbnpnhdmon
ocjdpmoallmgmjbbogfiiaofphbjgchh
ojggmchlghnjlapmfbnjholfjkiidbch
ciojocpkclfflombbcfigcijjcbkmhaf
mkpegjkblkkefacfnmkajcjmabijhclg
aflkmfhebedbjioipglgcbcmnbpgliof
omaabbefbmiijedngplfjmnooppbclkk
penjlddjkjgpnkllboccdgccekpkcbin
apenkfbbpmhihehmihndmmcdanacolnh
jiidiaalihmmhddjgbnbgdfflelocpak
nphplpgoakhhjchkkhmiggakijnkhfnd
fldfpgipfncgndfolcbkdeeknbbbnhcc
nnpmfplkfogfpmcngplhnbdnnilmcdcg
gdokollfhmnbfckbobkdbakhilldkhcj
fijngjgcjhjmmpcmkeiomlglpeiijkld
cgadeiniijaimpdmhfklcphfnglpkmll
pbpjkcldjiffchgbbndmhojiacbgflha
aheklkkgnmlknpgogcnhkbenfllfcfjb
ajcicjlkibolbeaaagejfhnofogocgcj
hjgoblidjnnnamdkinbichnfbmghmafd
gfenajajnjjmmdojhdjmnngomkhlnfjl
dfeccadlilpndjjohbjdblepmjeahlmm
hkkpjehhcnhgefhbdcgfkeegglpjchdc
jbkfoedolllekgbhcbcoahefnbanhhlh
lfochlioelphaglamdcakfjemolpichk
dppgmdbiimibapkepcbdbmkaabgiofem
emgfgdclgfeldebanedpihppahgngnle
keokhigifjinncljedmendkbikiakicj
ljpdiapgjljgaiiilgojopoonfnnpfgj
bbcinlkgjjkejfdpemiealijmmooekmp
gehmmocbbkpblljhkekmfhjpfbkclbph
apenkfbbpmhihehmihndmmcdanacolnh
niihfokdlimbddhfmngnplgfcgpmlido
jnmbobjmhlngoefaiojfljckilhhlhcj
abkahkcbhngaebpcgfmhkoioedceoigp
admmjipmmciaobhojoghlmleefbicajg
aflkmfhebedbjioipglgcbcmnbpgliof
cjookpbkjnpkmknedggeecikaponcalb
afbcbjpbpfadlkmhmclhkeeodmamcflc
bopcbmipnjdcdfflfgjdgdjejmgpoaab
canipghmckojpianfgiklhbgpfmhjkjg
cpmkedoipcpimgecpmgpldfpohjplkpp
aeblfdkhhhdcdjpifhhbdiojplfjncoa
agoakfejjabomempkjlepdflaleeobhb
ajkifnllfhikkjbjopkhmjoieikeihjb
ajkigpnleboodhdlminnlmldegieilfc
amkmjjmmflddogmhpjloimipbofnfjih
andhndehpcjpmneneealacgnmealilal
apnehcjmnengpnmccpaibjmhhoadaico
bcopgchhojmggmffilplmbdicgaihlkp
bedogdpgdnifilpgeianmmdabklhfkcn
bfogiafebfohielmmehodmfbbebbbpei
bifidjkcdpgfnlbcjpdkdcnbiooooblg
bkgplkpdgidlgmnlhdfakhcjfpfgjjkb
bkklifkecemccedpkhcebagjpehhabfb
blgcbajigpdfohpgcmbbfnphcgifjopc
bmhejbnmpamgfnomlahkonpanlkcfabg
bmikpgodpkclnkgmnpphehdgcimmided
bnfdmghkeppfadphbnkjcicejfepnbfe
bnfooenhhgcnhdkdjelgmmkpaemlnoek
bocpokimicclpaiekenaeelehdjllofo
bofddndhbegljegmpmnlbhcejofmjgbn
caljgklbbfbcjjanaijlacgncafpegll
cgddkajmbckbjbnondgfcbcojjjdnmji
chgfefjpcobfbnpmiokfjjaglahmnded
cihmoadaighcejopammfbmddcmdekcje
cmndjbecilbocjfkibfbifhngkdmjgog
cnlhokffphohmfcddnibpohmkdfafdli
dbfoemgnkgieejfkaddieamagdfepnff
dbgibbbeebmbmmhmebogidfbfehejgfo
dbgnhckhnppddckangcjbkjnlddbjkna
didegimhafipceonhjepacocaffmoppf
dlcobpjiigpikoobohmabehhmhfoodbb
dldjpboieedgcmpkchcjcbijingjcgok
dmjmllblpcbmniokccdoaiahcdajdjof
eajafomhmkipbjmfmhebemolkcicgfmd
ebfidpplhabeedpnhjnobghokpiioolj
efbglgofoippbgcjepnhiblaibcnclgk
eiaeiblijfjekdanodkjadfinkhbfgcd
einhphiffjfjogeofkpclobkcgennocm
einnioafmpimabjcddiinlhmijaionap
ejbidfepgijlcgahbmbckmnaljagjoll
ejjladinnckdgjemekebdpeokbikhfci
eljmjmgjkbmpmfljlmklcfineebidmlo
ellkdbaphhldpeajbepobaecooaoafpg
eokbbaidfgdndnljmffldfgjklpjkdoi
fcckkdbjnoikooededlapcalpionmalo
fdchdcpieegfofnofhgdombfckhbcokj
fdcnegogpncmfejlfnffnofpngdiejii
fdfemjpbhpcjeadhbblfifdldedefnhe
fdjamakpfbbddfjaooikfcpapjohcfmg
fdojfgffiecmmppcjnahfgiignlnehap
fooolghllnmhmmndgjiamiiodkpenpbb
fopmedgnkfpebgllppeddmmochcookhc
fpkhgmpbidmiogeglndfbkegfdlnajnf
gafhhkghbfjjkeiendhlofajokpaflmk
gejiddohjgogedgjnonbofjigllpkmbf
ghlmndacnhlaekppcllcpcjjjomjkjpg
ghmbeldphafepmbegfdlkpapadhbakde
gjkdbeaiifkpoencioahhcilildpjhgh
gjlmehlldlphhljhpnlddaodbjjcchai
gjnckgkfmgmibbkoficdidcljeaaaheg
gmohoglkppnemohbcgjakmgengkeaphi
gpnihlnnodeiiaakbikldcihojploeca
hcjhpkgbmechpabifbggldplacolbkoh
hdokiejnpimakedhajhdlcegeplioahd
heamnjbnflcikcggoiplibfommfbkjpj
hfajfpbjlmembfdlhakjmefnbhjddofb
hfdkpbblioghdghhkdppipefbchgpohn
hgbeiipamcgbdjhfflifkgehomnmglgk
hifafgmccdpekplomjjkcfgodnhcellj
hldllnfgjbablcfcdcjldbbfopmohnda
hmeobnfnfcmdkdcmlblgagmfpfboieaf
hnebcbhjpeejiclgbohcijljcnjdofek
hpcbfphmanablmeomioemmamedfffmpd
hpclkefagolihohboafpheddmmgdffjm
ibpjepoimpcdofeoalokgpjafnjonkpc
ieldiilncjhfkalnemgjbffmpomcaigi
ifckdpamphokdglkkdomedpdegcjhjdp
ifclboecfhkjbpmhgehodcjpciihhmif
igkpcodhieompeloncfnbekccinhapdb
ilhaljfiglknggcoegeknjghdgampffk
imlcamfeniaidioeflifonfjeeppblda
inlkhilmjmjomfcpdifpfgllhhlpnbej
iokeahhehimjnekafflcihljlcjccdbe
jfdlamikmbghhapbgfoogdffldioobgl
jhfjfclepacoldmjmkmdlmganfaalklb
jhgnbkkipaallpehbohjmkbjofjdmeid
jiepnaheligkibgcjgjepjfppgbcghmp
jiiigigdinhhgjflhljdkcelcjfmplnd
kamfleanhcmjelnhaeljonilnmjpkcjc
kfdniefadaanbjodldohaedphafoffoh
kfmlopbepahlcjbkfnnklglgibbopkbk
kglcipoddmbniebnibibkghfijekllbl
khhapgacijodhjokkcjmleaempmchlem
khpkpbbcccdmmclmpigdgddabeilkdpd
klghhnkeealcohjjanjjdaeeggmfmlpl
klnaejjgbibmhlephnhpmaofohgkpgkd
kmcfomidfpdkfieipokbalgegidffkal
kmhcihpebfmpgmihbkipmjlmmioameka
kmphdnilpmdejikjdnlbcnmnabepfgkh
lccbohhgfkdikahanoclbdmaolidjdfl
ldinpeekobnhjjdofggfgjlcehhmanlj
lfmmjkfllhmfmkcobchabopkcefjkoip
lgbjhdkjmpgjgcbcdlhkokkckpjmedgc
lgdfffagihonfnkcffpikpifhegcdkge
lkpmkhpnhknhmibgnmmhdhgdilepfghe
lmkncnlpeipongihbffpljgehamdebgi
lpilbniiabackdjcionkobglmddfbcjo
mfgccjchihfkkindfppnaooecgfneiii
mfhbebgoclkghebffdldpobeajmbecfk
mjgkpalnahacmhkikiommfiomhjipgjn
mlhdnjepakdfdaabohjgegnomlgeejep
mmhlniccooihdimnnjhamobppdhaolme
momakdpclmaphlamgjcndbgfckjfpemp
mpeengabcnhhjjgleiodimegnkpcenbk
naepdomgkenhinolocfifgehidddafch
nebnhfamliijlghikdgcigoebonmoibm
nhccebmfjcbhghphpclcfdkkekheegop
nhhldecdfagpbfggphklkaeiocfnaafm
nhihjlnjgibefgjhobhcphmnckoogdea
njimencmbpfibibelblbbabiffimoajp
nknhiehlklippafakaeklbeglecifhad
nlgbhdfgdhgbiamfdfmbikcdghidoadd
nopnfnlbinpfoihclomelncopjiioain
ojbcfhjmpigfobfclfflafhblgemeidi
ookjlbkiijinhpmnjffcofjonbfbgaoc
opnnmgopaggjpapnoknbphfpjfadbddc
papngmkmknnmfhabbckobgfpihpdgplk
pcndjhkinnkaohffealmlmhaepkpmgkb
pdgbckgdncnhihllonhnjbdoighgpimk
pdliaogehgdbhbnmkklieghmmjkpigpa
pmbjpcmaaladnfpacpmhmnfmpklgbdjb
pnbabdldpneocemigmicebglmmfcjccm
pocmplpaccanhmnllbbkpgfliimjljgo
ppdadbejkmjnefldpcdjhnkpbjkikoip
pnlccmojcmeohlpggmfnbbiapkmbliob
No Malware configuration.
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
166
Monitored processes
31
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start powershell.exe conhost.exe no specs #STEALC notepad.exe chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
664"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --field-trial-handle=5668,i,17065981577795507760,3917916030328994134,262144 --variations-seed-version=20251218-201203.402000 --mojo-platform-channel-handle=5808 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
133.0.6943.127
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\133.0.6943.127\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
680"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --field-trial-handle=6088,i,17065981577795507760,3917916030328994134,262144 --variations-seed-version=20251218-201203.402000 --mojo-platform-channel-handle=5720 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
133.0.6943.127
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\133.0.6943.127\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1652"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --string-annotations --enable-dinosaur-easter-egg-alt-images --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=6 --field-trial-handle=3260,i,17065981577795507760,3917916030328994134,262144 --variations-seed-version=20251218-201203.402000 --mojo-platform-channel-handle=3276 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Version:
133.0.6943.127
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\133.0.6943.127\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1900"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --field-trial-handle=5776,i,17065981577795507760,3917916030328994134,262144 --variations-seed-version=20251218-201203.402000 --mojo-platform-channel-handle=6100 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
133.0.6943.127
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\133.0.6943.127\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2000"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --string-annotations --extension-process --enable-dinosaur-easter-egg-alt-images --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=7 --field-trial-handle=4188,i,17065981577795507760,3917916030328994134,262144 --variations-seed-version=20251218-201203.402000 --mojo-platform-channel-handle=4224 /prefetch:2C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Version:
133.0.6943.127
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\133.0.6943.127\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2840"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --string-annotations --enable-dinosaur-easter-egg-alt-images --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=8 --field-trial-handle=4460,i,17065981577795507760,3917916030328994134,262144 --variations-seed-version=20251218-201203.402000 --mojo-platform-channel-handle=3032 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Version:
133.0.6943.127
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\133.0.6943.127\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
3552"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --field-trial-handle=5596,i,17065981577795507760,3917916030328994134,262144 --variations-seed-version=20251218-201203.402000 --mojo-platform-channel-handle=5580 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
133.0.6943.127
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
3580"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --field-trial-handle=5564,i,17065981577795507760,3917916030328994134,262144 --variations-seed-version=20251218-201203.402000 --mojo-platform-channel-handle=5548 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
133.0.6943.127
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
3640"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --field-trial-handle=5860,i,17065981577795507760,3917916030328994134,262144 --variations-seed-version=20251218-201203.402000 --mojo-platform-channel-handle=5488 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
133.0.6943.127
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
4328"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --field-trial-handle=6044,i,17065981577795507760,3917916030328994134,262144 --variations-seed-version=20251218-201203.402000 --mojo-platform-channel-handle=5720 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
133.0.6943.127
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\133.0.6943.127\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
Total events
12 059
Read events
12 056
Write events
3
Delete events
0

Modification events

(PID) Process:(6988) notepad.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(6988) notepad.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(6988) notepad.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
Executable files
0
Suspicious files
59
Text files
50
Unknown types
0

Dropped files

PID
Process
Filename
Type
7460chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\ClientCertificates\LOG.old~RFe73b5.TMP
MD5:
SHA256:
7460chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SegmentInfoDB\LOG.old~RFe73b5.TMP
MD5:
SHA256:
7460chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SegmentInfoDB\LOG.old
MD5:
SHA256:
7460chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\ClientCertificates\LOG.old
MD5:
SHA256:
7460chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old~RFe73c4.TMP
MD5:
SHA256:
7460chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\chrome_cart_db\LOG.old~RFe73c4.TMP
MD5:
SHA256:
7460chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
7460chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\PersistentOriginTrials\LOG.old~RFe73d4.TMP
MD5:
SHA256:
7460chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\chrome_cart_db\LOG.old
MD5:
SHA256:
7460chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old~RFe73d4.TMP
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
64
TCP/UDP connections
52
DNS requests
39
Threats
23

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5276
MoUsoCoreWorker.exe
GET
304
4.231.128.59:443
https://settings-win.data.microsoft.com/settings/v3.0/OneSettings/Client?OSVersionFull=10.0.19045.4046.amd64fre.vb_release.191206-1406&LocalDeviceID=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&AttrDataVer=186&OSUILocale=en-US&OSSkuId=48&App=WOSC&AppVer=&IsFlightingEnabled=0&TelemetryLevel=1&DeviceFamily=Windows.Desktop
US
whitelisted
4692
powershell.exe
GET
302
206.245.132.40:80
http://pow-leyton.com/
US
html
299 b
unknown
4692
powershell.exe
GET
200
206.245.132.250:80
http://206.245.132.250/sys_skyx.ffu
US
text
862 Kb
unknown
5316
svchost.exe
POST
400
40.126.32.74:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
203 b
whitelisted
5276
MoUsoCoreWorker.exe
GET
304
4.231.128.59:443
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?ProcessorClockSpeed=3094&FlightIds=&UpdateOfferedDays=4294967295&BranchReadinessLevel=CB&OEMManufacturerName=DELL&IsCloudDomainJoined=0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&sku=48&ActivationChannel=Retail&AttrDataVer=186&IsMDMEnrolled=0&ProcessorCores=6&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&TotalPhysicalRAM=6144&PrimaryDiskType=4294967295&FlightingBranchName=&ChassisTypeId=1&OEMModelNumber=DELL&SystemVolumeTotalCapacity=260281&sampleId=95271487&deviceClass=Windows.Desktop&App=muse&DisableDualScan=0&AppVer=10.0&OEMSubModel=J5CR&locale=en-US&IsAlwaysOnAlwaysConnectedCapable=0&ms=0&DefaultUserRegion=244&UpdateServiceUrl=http%3A%2F%2Fneverupdatewindows10.com&osVer=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceId=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&DeferQualityUpdatePeriodInDays=0&ring=Retail&DeferFeatureUpdatePeriodInDays=30
US
whitelisted
5316
svchost.exe
POST
200
40.126.32.74:443
https://login.live.com/RST2.srf
US
xml
1.24 Kb
whitelisted
5316
svchost.exe
POST
400
40.126.32.74:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
203 b
whitelisted
5316
svchost.exe
GET
200
23.11.41.157:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAz1vQYrVgL0erhQLCPM8GY%3D
NL
binary
471 b
whitelisted
1788
SIHClient.exe
GET
304
135.232.92.137:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
5316
svchost.exe
POST
400
40.126.32.74:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
203 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
4872
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5276
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
48.192.1.64:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
4692
powershell.exe
206.245.132.40:80
pow-leyton.com
FIBERSTATE
US
unknown
4692
powershell.exe
206.245.132.250:80
FIBERSTATE
US
unknown
5316
svchost.exe
40.126.32.74:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5316
svchost.exe
23.11.41.157:80
ocsp.digicert.com
AKAMAI-AMS
NL
whitelisted
3428
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 40.127.240.158
whitelisted
activation-v2.sls.microsoft.com
  • 48.192.1.64
whitelisted
google.com
  • 142.250.186.46
whitelisted
pow-leyton.com
  • 206.245.132.40
unknown
login.live.com
  • 40.126.32.74
  • 20.190.160.5
  • 20.190.160.22
  • 20.190.160.65
  • 20.190.160.17
  • 40.126.32.133
  • 20.190.160.67
  • 20.190.160.4
whitelisted
ocsp.digicert.com
  • 23.11.41.157
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
crl.microsoft.com
  • 184.24.77.27
  • 184.24.77.11
  • 184.24.77.34
  • 184.24.77.7
  • 184.24.77.23
  • 184.24.77.38
  • 184.24.77.42
  • 184.24.77.19
  • 184.24.77.37
whitelisted
www.microsoft.com
  • 23.52.181.212
whitelisted
slscr.update.microsoft.com
  • 135.232.92.137
whitelisted

Threats

PID
Process
Class
Message
4692
powershell.exe
Not Suspicious Traffic
ET INFO Windows Powershell User-Agent Usage
4692
powershell.exe
Not Suspicious Traffic
ET INFO Windows Powershell User-Agent Usage
4872
svchost.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
6988
notepad.exe
Misc activity
INFO [ANY.RUN] USER_AGENTS Suspicious User-Agent (Mozilla/5.0)
6988
notepad.exe
Misc activity
INFO [ANY.RUN] USER_AGENTS Suspicious User-Agent (Mozilla/5.0)
6988
notepad.exe
Misc activity
INFO [ANY.RUN] USER_AGENTS Suspicious User-Agent (Mozilla/5.0)
6988
notepad.exe
Misc activity
INFO [ANY.RUN] USER_AGENTS Suspicious User-Agent (Mozilla/5.0)
6988
notepad.exe
Malware Command and Control Activity Detected
ET MALWARE Win32/Stealc/Vidar Stealer Style Headers In HTTP POST M2
6988
notepad.exe
A Network Trojan was detected
ET MALWARE Win32/Stealc/Vidar Stealer Style Headers In HTTP POST M1
6988
notepad.exe
Misc activity
INFO [ANY.RUN] USER_AGENTS Suspicious User-Agent (Mozilla/5.0)
No debug info